
Drafting a risk management and compliance programme
Legal practitioners , as accountable institutions must develop, maintain and implement a risk management and compliance programme (RMCP) for combating money laundering, terrorist financing and proliferation financing (ML, TF and PF). In terms of the Financial Intelligence Centre Act (FIC Act), having an RMCP in place is a legislative requirement for all accountable institutions, including legal practitioners. An RMCP captures the institutions understanding of their assessment and exposure to risks of ML, TF and PF, and details what measures they will take to identify, manage and mitigate these risks. The accountable institutions RMCP must address all the requirements outlined in section 42 of the FIC Act. These include policy documents, processes, systems and controls employed in customer due diligence (identification and verification of clients), record keeping, reporting, application of the risk-based approach and related training of employees. Legal practitioners and all accountable institutions can capture their RMCP in documentation along the following themes: The RMCP should be drafted and implemented and based on the ML, TF and PF risks encountered specific to the individual institution. The RMCP documentation must be updated on an ongoing basis. In achieving a risk-based approach, accountable institutions must identify, assess, monitor, mitigate and manage the risk of ML, TF and PF. The account able institution should conduct an entity wide anti-money laundering, counter terrorist financing and counter proliferation financing risk assessment prior to drafting their RMCP. There are three types of risk assessments: Refer to public compliance communication 53 ( PCC 53 ) for an example of a client-risk assessment matrix. Guidance Note 7 also explains each of the risk factors which include client type, the delivery channel, geographic location, products and services. Legal practitioners must apply the risk assessment by taking into account the operational factors such as their business nature and size, products or services offered, and their geographic location. As an example, the business risk assessment of a law firm that provides only conveyancing services, would be different to that of a law firm that offers civillitigation. The RMCP for an accountable institution which does not provide a wide range of products and/or services could be relatively simple. Complex institutions offering a wide range of products and services or which deal with a diverse range of cli ents would be expected to have a more complex and multifaceted RMCP. As part of their FIC Act obligations, legal practitioners must identify and report to the FIC transactions or activities deemed to be suspicious and unusual. The FIC analyses this information to develop financial intelligence, which it shares with law enforcement, prosecutorial and other competent authorities for their investigations and applications for asset forfeiture. The person filing a suspicious and unusual transaction report (STR) or suspicious activity report (SAR) does not have to prove that the funds or activity involved are linked to a crime. STRs and SARs can be based on subjective suspicion and there is no monetary threshold applicable when filing an STR. The transaction or activity must be reported, irrespective of the amount of money involved. When a transaction has not been concluded, but the clients behaviour leads to the suspicion that the legal practitioners firm may be abused for money laundering, terrorist financing or proliferation financing, this must be reported in an SAR. All STRs and SARs must be submitted without delay, and no later than 15 days after a business be comes aware and/or suspicion is raised regarding an activity or transaction. The report must be filed via the FICs online registration and reporting platform, called goAML . Filing either of these reports does not prevent a business from continuing with the transaction. A pe
How does this affect your business?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Wansom is AI and can make mistakes.